Draft · updated 27 July 2026

Privacy policy

This policy describes how personal data is processed when you use PM Universe (pmuniverse.se). The policy reflects how the service is built: necessary cookies for sign-in and organisation, and optional Google Analytics on public pages after consent.

Placeholders to fill in: [Company name], [org. no.], [email], [address]. These are marked with square brackets in the text below.

1. Controller

The controller for processing in PM Universe is:

  • [Company name]
  • Organisation number: [org. no.]
  • Address: [address]
  • Email: [email]

If your organisation uses PM Universe as a customer, the organisation may in some cases be the controller for the project data entered in the service, while [Company name] acts as a processor. Any processor relationship is then governed separately.

2. What data we process

Depending on how you use the service, the following data may be processed:

  • Account details: email address, name (if provided), user ID and password (hashed, handled by the authentication service).
  • Organisation and membership: which organisation and projects you belong to, and role (e.g. admin or member).
  • Project data: data you or colleagues enter in PM Universe (planning, resources, budget, risks, status reports, etc.). Free-text fields may contain personal data if users enter it — users are asked to avoid unnecessary personal data.
  • Technical data: session cookies, selected organisation (`org_id`), and a local browser timestamp for idle sign-out.
  • Sign-in via SSO (optional): if the organisation has enabled Google or Microsoft sign-in, name and email may be received from the identity provider at sign-in.

3. Purposes and legal basis

PurposeLegal basis
Provide the account, sign-in and permissionsContract (use of the service) / legitimate interest in delivering the service
Store and display project data within your organisationContract / processor assignment
Send invitation and password-reset emailsContract / legitimate interest
Security (session, idle sign-out, access control)Legitimate interest
Traffic statistics on public pages (Google Analytics), only after consentConsent

We do not use personal data for marketing profiles or advertising networks. Analytics runs only if you accept analytics cookies.

4. Cookies and similar technologies

Necessary cookies are set without consent. Analytics cookies (Google Analytics) are set only if you approve them via the cookie banner.

Necessary cookies

Name / typePurposeStorage
sb-*(Supabase Auth)Keep you signed in and sync the session between server and browser (`httpOnly` where applicable)Session / per Auth
org_idRemember the selected organisation in multi-tenant mode (`httpOnly`, SameSite=Lax)30 days
analytics_consentRemember your choice about analytics cookies (granted/denied)1 year

Analytics cookies (after consent)

With consent, Google Analytics 4 is loaded on public pages (Google cookies, e.g. `_ga`). IP anonymisation is enabled in the configuration. You can change or withdraw your choice at any time via the controls below, via the “Change cookie settings” link in the footer on public pages, or by clearing the `analytics_consent` cookie.

Read more about how Google uses data: How Google uses data.

Manage cookie settings

Loading your cookie settings…

Local storage (not a cookie)

KeyPurpose
pm_idle_last_activitySync last activity across tabs so idle sign-out (about 30 minutes) works correctly

Fonts are loaded via Next.js (`next/font`) and hosted with the app — no separate tracking cookie from a font vendor is used in the client for this.

5. Recipients and sub-processors

To run the service, the following categories of providers are used. They may only process data under contract and for the stated purposes:

  • Supabaseauthentication, database (Postgres), RLS and auth-related emails (invite, password reset). Data is stored in an EU region (eu-west-1 per the service’s security documentation).
  • Vercelhosting and running the web application (including server functions and operational logs).
  • Google / Microsoftonly if SSO is enabled for your organisation; authentication then goes via the respective identity provider.
  • Google Analyticsonly after cookie consent; traffic statistics on public pages.
  • Stripepayments and subscriptions when the organisation upgrades from trial. Card details are handled by Stripe (PCI); we store customer/subscription IDs.

AI (Anthropic): An SDK exists in the codebase for future features but is not actively used in the app today. No user data is sent to Anthropic while AI features are not enabled. If that changes, this policy will be updated.

We do not sell personal data and do not share it with advertising networks.

6. Transfers outside the EU/EEA

Primary storage of application data is within the EU via Supabase (eu-west-1). The hosting provider Vercel may process technical data (e.g. request logs) in multiple regions. With SSO, Google or Microsoft may process authentication data under their terms, which may involve transfers outside the EU/EEA with appropriate safeguards (e.g. standard contractual clauses) at each provider.

7. Retention

  • Account details for as long as the account is active, and thereafter until the account is deleted by an administrator or on request.
  • Project data for as long as the organisation uses the service, or until data is deleted by an authorised user/admin. After cancellation or an expired trial there is normally a 14-day export window, after which the workspace is locked. Data may be retained for up to 90 days for reactivation before it can be deleted (see also Danger zone under Settings).
  • org_id cookie 30 days (or until cleared).
  • Session per Supabase Auth; the app also signs you out after about 30 minutes of inactivity.
  • Technical logs per each provider’s retention (Vercel/Supabase).

8. Your rights

Under the GDPR you have, among other things, the right to:

  • access to your personal data
  • rectification of inaccurate data
  • erasure ("the right to be forgotten") where applicable
  • restriction of processing
  • data portability where applicable
  • object to processing based on legitimate interest
  • lodge a complaint with the Swedish Authority for Privacy Protection (IMY)

Under Settings, an organisation admin can delete the entire organisation (including project data), and you can delete your own account (provided you are not the sole admin of a remaining organisation). Org admins can also download a ZIP export of organisation data (JSON/CSV) while the account is active or during the export window after cancellation. For other requests, contact [email].

Transactional emails about trial, cancellation and export reminders may be sent via our email provider (Resend). Payment-related emails (invoice, receipt) are sent by Stripe when payment is enabled.

9. Security

Access to data is limited with row-level security (RLS) per organisation, encryption in transit, and password handling via Supabase Auth. Session cookies are synced on the server side. In case of a suspected personal data breach, notification to IMY is assessed under applicable rules (within 72 hours when required).

10. Children

The service is aimed at professional project management and is not intended for children under 16.

11. Changes

We may update this policy when the service or legal requirements change. The current version is published on this page with the date of the latest update. Material changes (e.g. new tracking tools or AI processing) will be communicated clearly.

12. Contact

Questions about personal data or exercising your rights:

  • Email: [email]
  • Controller: [Company name] ([org. no.])